All AI News
    DiginomicaWednesday, August 5, 2026 6 min read
    AI

    "AI cannot be a black box" — buying cycles are getting longer, warns Blackline CEO Owen Ryan, but this too will pass

    AI governance scrutiny is adding 40-45 days to enterprise deal cycles, reshaping how CFOs evaluate software vendors.

    Koko brief

    AI governance scrutiny is adding 40-45 days to enterprise deal cycles, reshaping how CFOs evaluate software vendors.

    Tokenomics sticker shock and governance anxiety are stretching enterprise AI buying cycles by roughly six weeks on average, according to Blackline CEO Owen Ryan. Security, risk, and compliance teams now crowd the room alongside finance—demanding visibility into AI model governance, data sovereignty, and audit trails before signing. Gartner projects Fortune 500 firms will run 150,000-plus agents by 2028, yet fewer than one in five believe their governance can handle that scale. Longer cycles don't signal lost deals—they signal a matured, harder-to-shortcut evaluation.

    Watch: Whether vendors that lead with auditable, human-in-the-loop AI governance frameworks convert faster than those treating compliance as an afterthought.

    The tokenomics shock that seems to have taken so many enterprises by surprise when presented with the bill for their AI investment is bound to have a knock-on effect on buying decisions. There are already plenty of anecdotal stories coming in about organizations that were having an AI ‘fill your boots’ free-for-all, but whose Finance officers have now imposed pressure to moderate and cut back while questioning what value has been derived from spend to date. But it’s not just tokenomics that is causing buying behavior changes - an increased awareness of the complexities around AI adoption is also evident, taking over from the ‘silver bullet, go for it’ mindset that the out-of-control hype cycle has fostered. Owen Ryan, CEO at accounting firm Blackline has a personal example here: > We were recently selected for our first ever sovereign cloud opportunity with a large European company whose security and data requirements are among the most stringent in the world. We won the competitive evaluation and cleared the legal, security and technical reviews, and we are now working through the final details to close on this five-year eight-figure deal. Even with both sides aligned and committed to a June 30 close, a deal of this size and complexity simply takes longer to get across the line than either party would like. This dynamic is being replicated elsewhere, he confirms: > This elongated time line shows up mostly in our mega enterprise pursuits. Customers are evaluating more than just software now. They are also going much deeper into BlackLine's AI governance model, our product road map and how we sit inside their control environment before they sign. That pulls even more security, risk, compliance and IT professionals into the room alongside finance and everything is simply taking longer. More of these conversations have become formal build versus buy assessments and buying is beginning to come out far ahead. That clarity does not shorten the evaluation itself, so the time line stretches even when the outcome is clear. Overall, it’s just harder to predict deal timings today, he notes: > AI has put every Finance organization in the position of re-evaluating what they spend on and why, and that evaluation takes longer. Questions, questions Expanding on his point, Ryan says everything just takes longer these days: > Typically, in the enterprise space, we talk about nine months to a year and [while] these are not the most precise numbers, you could say that the deal cycle is elongated by another 40, 45 days based upon the work we're seeing. That's just an average - some of them could be longer, some of them could be a little bit quicker - but really what's driving it is, more than anything else, you have, in essence, a new technology in the marketplace, and all the people on the buy side from the customer, [you have] people asking new kinds of questions. These include the likes of how do organizations govern their AI’, how do they use different models, how do they/their chosen vendors protect their data, and what is the role of the sovereignty factor has they do business across borders? As Ryan notes: > There are more questions now about vulnerability because of AI-enabled hacking and how our defense and security around all that [works]. Blackline has been listening to its customers here, Ryan says, as well as other AI stakeholders to get a clear picture of the landscape emerging: > Over the past two quarters, we have had hundreds of meetings with CFOs, CIOs and CTOs, met with capital markets regulators, accounting standard setters, and the leadership of the seven largest global audit firms. We also met with the CEOs of adjacent Office of the CFO companies, large European enterprises focused on data sovereignty, BPO firms re-inventing themselves, and the frontier labs building the models everyone is working to deploy responsibly. Out of all of these conversations, the same theme keeps surfacing, he says namely that when AI scales, governance must scale with it. Agentic financial operations need a model where humans and AI work together, equally visible and equally governed. That’s a challenge many enterprises have yet to rise to - Gartner reckons the average Fortune 500 company will run more than 150,000 AI agents by 2028, up from fewer than 15 last year, but fewer than one in five companies believe they have the governance to manage that scale. There is an important audit lesson to be learned here, suggests Ryan: > AI cannot be a black box. Every step has to be evidenced. Trust issues For its part, Blackline looks to address these new needs, he says: > Our models are tested for bias and failure modes and signed off before reaching production, with humans reviewing, approving, overriding or halting the process at every stage. AI proposes, people decide. It is covered by the same internal controls over financial reporting framework as everything else in the close. That is the kind of trust the CFO requires from the partner behind the financial statements they personally attest to, and that trust takes years to earn. That trust does not happen by assertion alone. Ryan is completely clear about where the friction currently sits: > It is in adoption, not the product. Customers are careful about trusting AI inside closed critical accounting processes. Security and risk teams are getting involved earlier in the sales cycle, partly because many regulators still have not finalized guidance for AI. For its part, Blackline expects to have AIUC-1 certification in September. This is the independent third-party standard built for AI agent security and reliability coming out of the Artificial Intelligence Underwriting Company (AIUC). The certification is based on assessment of an AI agents production behavior across six risk areas - data privacy, security, safety, reliability, accountability, and society. It’s necessary to wear this sort of certification in place as a badge of pride, argues Ryan: > The market has tested us with more scrutiny than ever, scrutiny we are built to meet. We're responding with speed…The good thing is these are things we're well built to answer and respond to, but it does take more time as customers are asking those questions. For what it’s worth, the Blackline CEO doesn’t think the current prolongation of procurement practice is necessarily here to stay: > I don't think this is permanent…I just think that there's a learning experience that customers are going through. We certainly have learned a lot. We are equipping our teams with responses that they can bring to the market to sort of short circuit some of these additional questions that are coming through because we now know what the issues are. > > > And quite frankly, even if the customer doesn't know what the issues are, we're trying to bring those more front and center so that they know what they should be asking about and thinking about. My take Of course, at this point, the word ‘SaaSpocalypse’ can’t be far from discussion, can it? Surely a super-dooper Large Language Model (LLM) from a frontier AI firm is going to come along any day now and enable organizations to throw off the shackles of applications such as those on offer from Blackline in order to deliver AI-enabled Finance at scale? Ryan is phlegmatic: > One of the largest pharmaceutical companies in the world tested whether they could build its record-to-report workflows on a general purpose LLM. They learned quickly that a model generating suggestions cannot co-ordinate a full workflow the way our multi-agent architecture does with the transparency auditors require built in from the start. So the company chose to go deeper with BlackLine instead...A customer does not need to build a new governance framework to deploy AI and finance because BlackLine already is that framework. SaaSpocalypse postponed…again.Anyone would think it isn’t really happening, eh?

    Key takeaways
    • 01Tokenomics sticker shock and governance anxiety are stretching enterprise AI buying cycles by roughly six weeks on average, according to Blackline CEO Owen Ryan.
    • 02Security, risk, and compliance teams now crowd the room alongside finance—demanding visibility into AI model governance, data sovereignty, and audit trails before signing.
    • 03Gartner projects Fortune 500 firms will run 150,000-plus agents by 2028, yet fewer than one in five believe their governance can handle that scale.
    • 04Longer cycles don't signal lost deals—they signal a matured, harder-to-shortcut evaluation.

    Don't miss tomorrow's

    The Daily Pulse in your inbox each morning — sourced and linked.

    How often
    Keep going — across the app